Backdoor.Win32.Delf.np
(Backdoor.Win32.Delf.np)

by ?

Written in Delphi, compressed with UPX

Made in China

more in this category


dropped file:
c:\WINDOWS\WINDOWSYN.EXE
size: 161,280 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
data: C:\WINDOWS\WINDOWSYN.EXE 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "C:\WINDOWS\WINDOWSYN.EXE"
data: C:\WINDOWS\WINDOWSYN.EXE 
	
	
tested on Windows XP
September 15, 2004

MegaSecurity